{"id":1135,"date":"2022-11-23T19:03:55","date_gmt":"2022-11-23T18:03:55","guid":{"rendered":"https:\/\/aso.mariol03.es\/?p=1135"},"modified":"2022-11-23T19:03:56","modified_gmt":"2022-11-23T18:03:56","slug":"iniciar-sesion-con-los-usuarios-de-ad-en-pfsense","status":"publish","type":"post","link":"https:\/\/aso.mariol03.es\/index.php\/2022\/11\/23\/iniciar-sesion-con-los-usuarios-de-ad-en-pfsense\/","title":{"rendered":"Iniciar sesi\u00f3n con los usuarios de AD en PFsense."},"content":{"rendered":"\n<p>PFsense permite que el usuario se pueda autenticar desde un servidor LDAP, Active Directory internamente usar el protocolo LDAP, aunque esta bloqueado por el firewall de windows. Si creamos una regla que permita el trafico podemos acceder al servidor LDAP que integra AD y usar los usuarios del dominio de Active Directory en el servidor PFsense.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"1040\" height=\"779\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/Captura-de-pantalla-de-2022-11-23-18-38-38.png\" alt=\"\" class=\"wp-image-1144\"\/><\/figure><\/div>\n\n\n<p>Una vez permitido el trafico LDAP vamos a PFsense y a\u00f1adimos un servidor de autenticaci\u00f3n.<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/Captura-de-pantalla-de-2022-11-23-18-26-09.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"1185\" height=\"290\" data-id=\"1145\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/Captura-de-pantalla-de-2022-11-23-18-26-09.png\" alt=\"\" class=\"wp-image-1145\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP01.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"1156\" height=\"674\" data-id=\"1149\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP01.jpg\" alt=\"\" class=\"wp-image-1149\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP02.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"1141\" height=\"187\" data-id=\"1146\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP02.jpg\" alt=\"\" class=\"wp-image-1146\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP03.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"1138\" height=\"780\" data-id=\"1150\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP03.jpg\" alt=\"\" class=\"wp-image-1150\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP06.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"983\" height=\"309\" data-id=\"1147\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP06.jpg\" alt=\"\" class=\"wp-image-1147\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP07.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"903\" height=\"438\" data-id=\"1148\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP07.jpg\" alt=\"\" class=\"wp-image-1148\"\/><\/a><\/figure>\n<\/figure>\n\n\n\n<p>Una vez lo hallamos a\u00f1adido lo tendremos que habilitar para que se use pueda usar en el momento de inicio de sesi\u00f3n.<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-3 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP08.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"1159\" height=\"573\" data-id=\"1152\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP08.jpg\" alt=\"\" class=\"wp-image-1152\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP09.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"913\" height=\"501\" data-id=\"1151\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP09.jpg\" alt=\"\" class=\"wp-image-1151\"\/><\/a><\/figure>\n<\/figure>\n\n\n\n<p>Luego al comprobar no funcionara ya que a los usuario de AD no le hemos dado el privilegio de inicio de sesi\u00f3n en la p\u00e1gina de configuraci\u00f3n.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"711\" height=\"359\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP10.jpg\" alt=\"\" class=\"wp-image-1153\"\/><\/figure><\/div>\n\n\n<p>Para arreglar esto debemos crear un grupo remoto con el mismo nombre de un grupo de active directory, a este grupo se le da el privilegio de entrar en las p\u00e1ginas de configuraci\u00f3n.<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-5 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/Captura-de-pantalla-de-2022-11-23-18-26-36.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"1149\" height=\"286\" data-id=\"1154\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/Captura-de-pantalla-de-2022-11-23-18-26-36.png\" alt=\"\" class=\"wp-image-1154\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/Captura-de-pantalla-de-2022-11-23-18-26-59.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"1160\" height=\"528\" data-id=\"1156\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/Captura-de-pantalla-de-2022-11-23-18-26-59.png\" alt=\"\" class=\"wp-image-1156\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/Captura-de-pantalla-de-2022-11-23-18-27-18.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"1192\" height=\"771\" data-id=\"1155\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/Captura-de-pantalla-de-2022-11-23-18-27-18.png\" alt=\"\" class=\"wp-image-1155\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/Captura-de-pantalla-de-2022-11-23-18-58-40.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"441\" height=\"475\" data-id=\"1157\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/Captura-de-pantalla-de-2022-11-23-18-58-40.png\" alt=\"\" class=\"wp-image-1157\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/Captura-de-pantalla-de-2022-11-23-18-58-46.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"435\" height=\"474\" data-id=\"1158\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/Captura-de-pantalla-de-2022-11-23-18-58-46.png\" alt=\"\" class=\"wp-image-1158\"\/><\/a><\/figure>\n<\/figure>\n\n\n\n<p>Cuando tengamos un usuario en el grupo al que le hemos dado permisos, podremos iniciar sesi\u00f3n en la configuraci\u00f3n web.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"1164\" height=\"762\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/Captura-de-pantalla-de-2022-11-23-18-59-31.png\" alt=\"\" class=\"wp-image-1159\"\/><\/figure><\/div>\n\n\n<p>Otra cosa que podemos hacer es habilitar el inicio de sesi\u00f3n al portal cautivo para ello tenemos que cambiar el servidor de autenticaci\u00f3n en la configuraci\u00f3n de este.<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-7 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP11.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"1160\" height=\"575\" data-id=\"1162\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP11.jpg\" alt=\"\" class=\"wp-image-1162\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP12.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"408\" height=\"549\" data-id=\"1160\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP12.jpg\" alt=\"\" class=\"wp-image-1160\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP13.jpg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" loading=\"lazy\" width=\"1157\" height=\"246\" data-id=\"1161\" src=\"https:\/\/aso.mariol03.es\/wp-content\/uploads\/2022\/11\/PF-sense_LDAP13.jpg\" alt=\"\" class=\"wp-image-1161\"\/><\/a><\/figure>\n<\/figure>\n","protected":false},"excerpt":{"rendered":"<p>PFsense permite que el usuario se pueda autenticar desde un servidor LDAP, Active Directory internamente usar el protocolo LDAP, aunque esta bloqueado por el firewall de windows. Si creamos una regla que permita el trafico podemos acceder al servidor LDAP que integra AD y usar los usuarios del dominio de Active Directory en el servidor &hellip; <\/p>\n<p><a class=\"more-link btn\" href=\"https:\/\/aso.mariol03.es\/index.php\/2022\/11\/23\/iniciar-sesion-con-los-usuarios-de-ad-en-pfsense\/\">Seguir leyendo<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,5],"tags":[13,17,22,26,28,43,35],"_links":{"self":[{"href":"https:\/\/aso.mariol03.es\/index.php\/wp-json\/wp\/v2\/posts\/1135"}],"collection":[{"href":"https:\/\/aso.mariol03.es\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aso.mariol03.es\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aso.mariol03.es\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aso.mariol03.es\/index.php\/wp-json\/wp\/v2\/comments?post=1135"}],"version-history":[{"count":3,"href":"https:\/\/aso.mariol03.es\/index.php\/wp-json\/wp\/v2\/posts\/1135\/revisions"}],"predecessor-version":[{"id":1163,"href":"https:\/\/aso.mariol03.es\/index.php\/wp-json\/wp\/v2\/posts\/1135\/revisions\/1163"}],"wp:attachment":[{"href":"https:\/\/aso.mariol03.es\/index.php\/wp-json\/wp\/v2\/media?parent=1135"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aso.mariol03.es\/index.php\/wp-json\/wp\/v2\/categories?post=1135"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aso.mariol03.es\/index.php\/wp-json\/wp\/v2\/tags?post=1135"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}